spring-projects / spring-projects/spring-security

SEC-2148: AccessDecisionVoters should return an AccessDecision instead of int

Open
#2,374 0 comments 2 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

in: core type: enhancement type: jira
Dominant language
Java
Stars
9.6k
Forks
6.3k
Avg merge
2d 11h
Merged PRs (30d)
52

Description

Janning Vygen (Migrated from SEC-2148) said:

An AccessDecisionManager throws an AccessDeniedException (ADE) which is handled later by an ExceptionTranslationFilter and AccessDeniedHandler. Inside AccessDeniedHandler we would like to forward to different error pages depending on the cause of the ADE.

But the AccessDecisionManager is just asking AccessDecisionVoter and it just returns an int for ACCESS_GRANTED or ACCESS_DENIED. It would be nice if an AccessDecisionVoter would return an AccessDecision which can hold the pure decision like granted/denied and a cause if the access was denied.

The AccessDecisionManager could then throw an ADE containing the accessDecision. The AccessDeniedHandler can grab this decision and decide what to show to the user.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the AccessDecisionVoter and AccessDecisionManager entry points described in the issue, then trace how AccessDeniedException reaches ExceptionTranslationFilter and AccessDeniedHandler. Determine the API and compatibility changes needed for a decision carrying a denial cause; done means the handler can distinguish denial causes while existing access decisions remain supported.

Written by the indexing model from the issue text.

Assessment

Tech stack
java, spring
Domain
authorization, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.